Prosecution Insights
Last updated: October 02, 2026
Application No. 18/822,799

METHODS, DEVICES AND SYSTEMS FOR TRUSTWORTHINESS CERTIFICATION OF INFERENCE REQUESTS AND INFERENCE RESPONSES

Non-Final OA §101§103
Filed
Sep 03, 2024
Priority
Mar 03, 2022 — continuation of PCTCN2022079010
Examiner
SINGH, AMRESH
Art Unit
Tech Center
Assignee
Huawei Technologies Co., Ltd.
OA Round
1 (Non-Final)
76%
Grant Probability
Favorable
1-2
OA Rounds
1y 7m
Est. Remaining
98%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
475 granted / 623 resolved
+16.2% vs TC avg
Strong +22% interview lift
Without
With
+21.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 8m
Avg Prosecution
15 currently pending
Career history
654
Total Applications
across all art units

Statute-Specific Performance

§101
17.9%
-22.1% vs TC avg
§103
47.7%
+7.7% vs TC avg
§102
15.9%
-24.1% vs TC avg
§112
5.6%
-34.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 623 resolved cases

Office Action

§101 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Claims 1-20 are presented for examination. This is a Non-Final Action. Claim Rejections - 35 U.S.C. §101 35 U.S.C. §101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 USC 101 as directed to an abstract idea without significantly more. With respect to independent claims 1 and 11 , specifically claim 1 recites “encoding, using a linear block encoder, an input data vector obtained based on the input data to generate an encoded input vector”. This limitation encompasses applying an encoding matrix to an input vector through arithmetic operations. Paragraph 258 in specification discloses the encoding operation as multiplication of an input vector by an encoding matrix. For a small vector, the operation can practically be performed using pen and paper. For example, applying linear encoding rules that calculate the sum and difference of the two input values in the vector (2, 1) produces the encoded vector (3,1). Neither claim imposes a vector size, numerical precision or processing rate requirements that exclude such manually executable operation. Accordingly, the underlying encoding operation falls within the mental process. This judicial exception is not integrated into a practical application. At step 2A, prong two, claim(s) 1 and 11 recites the additional elements of “generating an inference request for a deep neural network (DNN), the inference request comprising input data for the DNN; transmitting the inference request to a computing system that hosts the DNN, the inference request including the encoded input vector; and receiving an inference response from the computing system hosting the DNN, the inference response comprising a certified inference data vector generated by the DNN based on the input data.” Claim 11 recites corresponding operations, with the received inference vector generated based on “the input data obtained”, and additionally specifies a processor coupled with a non-transitory computer-readable medium storing executable instructions. The additional elements utilize a remote DNN environment without specifying a technical interaction that improves the functioning of the computer, communication system or DNN. They do not establish a particular machine or transformation that meaningfully applies the exception beyond information processing and data outputting. Furthermore, The certification in the limitations is recited as a required characteristic of the received result, without specifying a certification operation or a technical relationship though which the input encoding enables certification. The claims thus require the result of certification without claiming a particular mechanism for accomplishing it. Hence the additional elements as a whole do not recite any specific improvement to computer technology, a particular machine implementing the process in a non-generic manner, a transformation of an article to a different state or thing, or any other meaningful limitation that applies the abstract idea in a manger that imposes a meaningful limit on the claim. Instead, the additional element simply applies the abstract idea using generic data processing operations, which amounts to implementing the mental processes using a computer environment. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea. The claims, 1, and 11 at step 2B, do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As explained with respect to Step 2A Prong Two, the additional elements as recited in step 2A prong 2 recite conventional computer executing routine data manipulation and outputting in a DNN environment. No elements individually or in combination adds “significantly more” than the abstract idea hence are no more than well-understood, routine and conventional computer functions that merely apply the abstract idea on a generic computer. When viewed as an ordered combination, these additional elements do not integrate the abstract idea into a practical application and do not add significantly more than the abstract idea itself. According, claim 1 is ineligible under 101. With respect to independent claims 6 and 16 , specifically claim 6 recites “encoding, using a linear block encoder, the input data vector to obtain an actual encoded input vector; obtaining a trustworthiness score representative of a comparison between the estimated encoded input vector and the actual encoded input vector; and responsive to determining that the trustworthiness score exceeds a threshold”. This limitation encompasses applying an encoding matrix to an input vector through arithmetic operations. Paragraph 258 in specification discloses the encoding operation as multiplication of an input vector by an encoding matrix. For a small vector, the operation can practically be performed using pen and paper. For example, applying linear encoding rules that calculate the sum and difference of the two input values in the vector (2, 1) produces the encoded vector (3,1). Neither claim imposes a vector size, numerical precision or processing rate requirements that exclude such manually executable operation. Furthermore, a user can easily compare two different vectors and determine whether a score exceeds a threshold based on observation/evaluation. Accordingly, the underlying encoding operation falls within the mental process. This judicial exception is not integrated into a practical application. At step 2A, prong two, claim(s) 6 and 11 recites the additional elements of “radio access network (RAN) node; receiving an inference request for a deep neural network (DNN) from an electronic device, the inference request including an input data vector; transmitting the inference request to a computing system that hosts the DNN; receiving an inference response from the computing system, the inference response including an output data vector generated by the DNN based on the input data vector; obtaining, based on the output data vector, an estimated encoded input vector; transmitting the output data vector to the electronic device.” Claim 16 recites additional elements “apparatus, at least one processor coupled with non-transitory computer-readable medium storing instructions, when the instructions executed by a computer, cause the apparatus to perform operations”. The additional elements are considered individually and in combination are elements merely invoking a generic computer environment (processor, database, memory) and basic data-gathering or outputting functions (MPEP 21.96.05(f)) hence reciting insignificant extra solution activities. The additional elements utilize a remote DNN environment without specifying a technical interaction that improves the functioning of the computer, communication system or DNN. Hence the additional elements as a whole do not recite any specific improvement to computer technology, a particular machine implementing the process in a non-generic manner, a transformation of an article to a different state or thing, or any other meaningful limitation that applies the abstract idea in a manger that imposes a meaningful limit on the claim. Instead, the additional element simply applies the abstract idea using generic data processing operations, such as mere data manipulation and outputting, which amounts to implementing the mental processes using a computer environment. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea. The claims, 6 and 16 at step 2B do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As explained with respect to Step 2A Prong Two, the additional elements as recited in step 2A prong 2 recite conventional computer executing routine data manipulation and outputting in a DNN environment. No elements individually or in combination adds “significantly more” than the abstract idea hence are no more than well-understood, routine and conventional computer functions that merely apply the abstract idea on a generic computer. When viewed as an ordered combination, these additional elements do not integrate the abstract idea into a practical application and do not add significantly more than the abstract idea itself. According, claim 6 is ineligible under 101. Claims 2-5, 7-10, 12-15 and 17-20 are dependent claims and do not recite any additional elements that would amount to significantly more than the abstract idea. Specifically, Claim 2. With respect to step 2A prong 2 “ transmitting a request to initialize coded transmission for inference.” recites additional elements of insignificant extra solution activity. With respect to step 2B the recited insignificant extra solution activity is recited at a high level of generality which are well-understood, routine and conventional as data outputting (transmitting or receiving data). Claim 3. With respect to step 2A prong 2 “receiving, responsive to the transmitting the request to initialize the coded transmission for inference, a linear block encoding matrix.” recites additional elements of insignificant extra solution activity. With respect to step 2B the recited insignificant extra solution activity is recited at a high level of generality which are well-understood, routine and conventional as data outputting (transmitting or receiving data). Claim 4. With respect to step 2A prong 2 “receiving, responsive to the transmitting the request to initialize the coded transmission for inference, an inferred data vector decoding matrix.” recites additional elements of insignificant extra solution activity. With respect to step 2B the recited insignificant extra solution activity is recited at a high level of generality which are well-understood, routine and conventional as data outputting (transmitting or receiving data). Claim 5. With respect to step 2A prong 1 “decoding, using an output data vector decoding matrix, the encoded output data vector to obtain a decoded output data vector.” recites abstract idea of mental steps (observation & evaluation). For example, a decoding matrix can map encoded values (u,v) to decoded values (u-v, v), an evaluation that can practically be performed mentally or with help of pen and paper. Claim 7. With respect to step 2A prong 1 “wherein the trustworthiness score comprises a squared difference between the estimated encoded input vector and the actual encoded input vector.” recites abstract idea of mental steps (observation & evaluation), a person can choose or determine algorithms based on search goals. Claim 8. With respect to step 2A prong 2 “transmitting the inference request to an inference neural network, wherein the inference neural network is configured to approximate a non-linear function.” recites additional elements of insignificant extra solution activity. With respect to step 2B the recited insignificant extra solution activity is recited at a high level of generality which are well-understood, routine and conventional as data outputting (transmitting or receiving data). Claim 9. With respect to step 2A prong 2 “providing the output data vector to a certification neural network, where the certification neural network has been trained to output the estimated encoded input vector responsive to receiving the output data vector received as output of the non-linear function.” recites additional elements of insignificant extra solution activity. With respect to step 2B the recited insignificant extra solution activity is recited at a high level of generality which are well-understood, routine and conventional as data outputting (transmitting or receiving data). Claim 10. With respect to step 2A prong 2 “receiving, from a provider of the inference neural network, a linear block encoding matrix.” recites additional elements of insignificant extra solution activity. With respect to step 2B the recited insignificant extra solution activity is recited at a high level of generality which are well-understood, routine and conventional as data outputting (transmitting or receiving data). Claims 11-15 is similar to claims 1-5 hence rejected similarly. Claims 16-20 is similar to claims 6-10 hence rejected similarly. In view of compact prosecution, if claims 1 and 11 were further amended to incorporate clarification based on paragraphs 258-265 in specification which describes coded communications, certification and protection against counterfeit-model training might overcome the abstract idea. Specifically, if the receiving limitation in claims 1 and 11, was amended to recite “receiving, from the computer system via a radio access network (RAN) node through which the inference request is transmitted, an inference response comprising an encoded output data vector representing an inference result generated by the DNN based on the input data, wherein the RAN node stores the encoded input vector, applies a class-specific reverse certification DNN to the encoded output data vector to generate an estimated encoded input vector and forwards the encoded output data vector to the electronic device only upon determining that a squared difference between the estimated encoded input vector and the stored encoded input vector is below a threshold; and decoding, using an output data vector decoding matrix, the encoded output data vector to obtain the certified inference data vector.” For claims 6 and 16, In view of compact prosecution, if claim were further amended to incorporate clarification based on paragraphs 177, 178, 180 and 182 in specification “wherein the RAN node receives, from the computing system, a token indication associated with the electronic device and uses the token indication to select a stored pair comprising a linear block encoding matrix specific to the electronic device and corresponding parameters of certification DNN; wherein the encoding uses the selected linear block encoding matrix; and wherein obtaining the estimated encoded input vector comprises providing the output data vector to the certification DNN configured with the selected parameters, the certification DNN having been trained, using outputs of the DNN for training input vectors, to minimize squared error between estimated encoded input vectors and the training input vectors encoded using the selected linear block encoding matrix. This adds a concrete verification mechanism tied to the requesting device. Claim 16 would require “wherein the apparatus is a radio access network (RAN) node, and the operations further comprise” These would overcome the abstract idea and move the application towards allowance. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-5 and 11-15 are rejected under 35 U.S.C. 103 as being unpatentable over Karame et al. (US 2021/0112038) in view of Hashemi et al. (Darknight – NPL) further in view of Liu et al. (US 2020/0110993 – IDS) 1. Karame teaches, A method performed at an electronic device, the method comprising (Fig 1-2, Paragraph 41, Karame): generating an inference request for a deep neural network (DNN), the inference request comprising input data for the DNN (Fig 4, Paragraphs 54 & 62 – teaches mode f can include an neural network such as DNN and client 120 can issue classification requests through the secure communication channel established with the enclave 320, the request’s input as “a classification query x (i.e., source data), Karame); transmitting the inference request to a computing system that hosts the DNN (Figs 1-2, fig 4; Paragraph 42, 54 & 62 – teaches the client transmits the classification request to host 110. The hosting computing system includes its trusted and untrusted processing components, Karame); and receiving an inference response from the computing system hosting the DNN (Fig 4, Paragraph 63 – teaches the client receives the host’s classification result in response to its request, Karame). Karame does not explicitly teach, encoding, using a linear block encoder, an input data vector obtained based on the input data to generate an encoded input vector; the inference request including the encoded input vector; and the inference response comprising a certified inference data vector generated by the DNN based on the input data. However, Hashemi teaches, encoding, using a linear block encoder, an input data vector obtained based on the input data to generate an encoded input vector (Fig. 1, Section 3.2 & 3.3 & EQ. 1 – teaches Darknight uses matrix masking to linearly combine the inputs and add a random noise to them. Eq (1) and section 3.2 expressly calls the combined input “coded inputs”, - thus disclosing the client performs the data-only linear combination portion of Eq. (1). The input block represented as a vector and it coded outputs as an encoded vector (therefore Linear block encoder), Hashemi); the inference request including the encoded input vector (Fig 1:1, Section 3.2 – teaches a batch of training/inference input data set is encrypted by the client using a mutually agreed keys with SGX and sent to the server. Fig 1:3 and Section 3.3, Eq. (1) supplies the separate input combination operation, Hashemi). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which said subject matter pertains to modify Karame’s inference system by performing the data only linear combination portion of Hashemi’s matrix masking operation at the client and including the resulting encoded input vector in the inference request. Hashemi identifies limited SGX resources and explains that its binding operations are substantially less complex than DNN computation (Sections 3.2-3.3). Performing this preprocessing at the client, where the input data already reside, would reduce the enclave’s share of the input coding workload without requiring the client to possess the DNN’s model weights. The corresponding coefficients could be supplied through Karame’s secure channel (Paragraph 61), while the host retains random masking, unbinding, and nonlinear processing. A reasonable expectation of success follows because the host’s addition of the masking term to the client computed linear combination produces the same code input defined by Hashemi’s Equation (1), preserving the subsequent decoding and DNN processing. However, Liu teaches, the inference response comprising a certified inference data vector generated by the DNN based on the input data (Figs 1A-1C and 3, Paragraph 21 – teaches a match result may serve to authenticate the results of the system; Paragraph 22 - teaches the system can communicate signatures for matching and/or certification of authenticity as a result of the testing; Fig 1B, Paragraph 28 – teaches the output of output layer 154 may include an inference resulting from processing of the input by neural network 122; Paragraph 45 – teaches if the matching succeeds, then the deployed system DNN is determined as an authentic version of the DNN is determined as an authentic version of the DNN and the system is authenticated). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which said subject matter pertains to modify the combination of Karame and Hashemi system to incorporate Liu’s signature based verification at the host and return the corresponding inference vector after successful authentication. Liu teaches augmenting a DNN with signature network and comparing its signature against an available original model signature generated from the same input to authenticate the inference results and deployed model (Fig 1A-1C and 3, Paragraphs 18-21 and 45). The motivation would have been to detect indications of model alteration and verify the authenticity of remote inference results before delivering them for client use. A reasonable expectation of success exists because Hashemi’s host recovers unblinded DNN values suitable for the signature network processing, while Karame already provides the host to client inference response path; verification would therefore precede transmission of the corresponding inference vector (Section 3.2-3.3, Hashemi; Paragraph 63, Karame). 2. The combination of Karame, Hashemi and Liu teach, The method of claim 1, further comprising: transmitting a request to initialize coded transmission for inference (Fig 5:502-508, Paragraph 56 – teaches in response to modeling request (i.e. a deep learning request) from client 120, host 110 can initialize the computing infrastructure – discloses client transmitted request that triggers preparation of the inference infrastructure and establishment of a communication session before source-data transmission, this setup would additionally initiate the coded input transmission mode, Karame). 3. The combination of Karame, Hashemi and Liu teach, The method of claim 2, further comprising: receiving, responsive to the transmitting the request to initialize the coded transmission for inference (Fig 5:502-508, Paragraph 72 – teaches client 120 can establish a secure communication session with TEE 114 (e.g., with the first enclave 320) – discloses request-responsive preparation and establishment of a secure session , Karame), a linear block encoding matrix (Fig 1, Section 3.3, Eq. (1) – DarKnight uses matrix masking to linearly combine the input and add a random noise to them. The scalars are represented by matrix A, which are dynamically generated for each batch and securely stored inside SGX for unblinding, Hashemi). 4. The combination of Karame, Hashemi and Liu teach, The method of claim 2, further comprising: receiving, responsive to the transmitting the request to initialize the coded transmission for inference (Fig 5:502-508, Paragraph 72 – teaches client 120 can establish a secure communication session with TEE 114 (e.g., with the first enclave 320) – discloses request-responsive preparation and establishment of a secure session , Karame), an inferred data vector decoding matrix (Fig 1:6-7; Section 3.3 – teaches the K+1 outputs… returned the GPU must be unblinded to extract the original results (EQ. 2) expressly provides Y . The ellipsis omits the output-variable notation, Hashemi). 5. The combination of Karame, Hashemi and Liu teach, The method of claim 1, wherein the inference response includes an encoded output data vector, and the method further comprises (Fig 4 – host-to-client result path; Paragraph 20 – teaches The TEE can encrypt the classification in a manner only decipherable by the client (e.g., with a public key that the client supplies); Paragraph 23 – teaches each piece of data can be matrix (e.g., unidimensional matrix such as a vector); Paragraph 63 – teaches the second enclave obtains the classification result y = f(x) and sends it to the client through the secure channel – discloses the encrypted classification corresponds to an encoded output vector returned to the client, Karame): decoding, using an output data vector decoding matrix, the encoded output data vector to obtain a decoded output data vector (Fig 1: 7, Session 3.2 – teaches SGX decodes the received computational outputs using DarKnight’s decoding strategy and then performs any non-linear operations within SGX; Session 3.3, Eq. (2): Y = Y*A^-1 - ). Claims 11-15 is similar to claims 1-5 hence rejected similarly. Allowable Subject Matter Claim 6-10 and 16-20 allowed. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Schneider et al. (US 2021/0397940) – teaches client side behavior classification, reputation management and authenticated neural network updates (Abstract, Fig 3-5). Any inquiry concerning this communication or earlier communications from the examiner should be directed to AMRESH SINGH whose telephone number is (571)270-3560. The examiner can normally be reached Monday-Friday 8am-5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ann J. Lo can be reached at (571) 272-9767. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /AMRESH SINGH/Primary Examiner, Art Unit 2159
Read full office action

Prosecution Timeline

Sep 03, 2024
Application Filed
Sep 21, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748633
WEIGHTED AUTO-SHARDING
2y 11m to grant Granted Sep 29, 2026
Patent 12717480
PERFORMING SECONDARY COPY OPERATIONS BASED ON DEDUPLICATION PERFORMANCE
2y 0m to grant Granted Aug 25, 2026
Patent 12705508
METHOD FOR ADDING PREDICTION RESULTS AS TRAINING DATA USING AI PREDICTION MODEL
3y 4m to grant Granted Aug 11, 2026
Patent 12705229
SYSTEMS AND METHODS FOR GLOBAL CONSISTENCY IN DISTRIBUTED SHARED-DATA DATABASES
2y 7m to grant Granted Aug 11, 2026
Patent 12699708
METHOD, SYSTEM, AND COMPUTER PROGRAM PRODUCT FOR IMPLEMENTING A STANDBY DATABASE WITH REAL-TIME SECURE SUBSETTING
5y 0m to grant Granted Aug 04, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
76%
Grant Probability
98%
With Interview (+21.9%)
3y 8m (~1y 7m remaining)
Median Time to Grant
Low
PTA Risk
Based on 623 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month